CVE-2007-5274 describes a security vulnerability in Sun Java Runtime Environment (JRE) affecting various versions when used with Firefox or Opera browsers. This flaw allows remote attackers to bypass the security model for JavaScript outbound connections through a DNS rebinding attack, leveraging the LiveConnect API. The attack involves a discrepancy where JavaScript download uses browser DNS resolution, while socket operations rely on separate JVM DNS resolution, potentially leading to unauthorized data access. The vulnerability has a CVSS score of 2.6 (AV:N/AC:H/Au:N/C:N/I:P/A:N), indicating a network-based attack with high complexity, requiring no authentication, and primarily impacting integrity with no confidentiality or availability impact. Its FAUCET Risk Score is 8/100, suggesting a low overall risk. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a lack of widespread attention or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:*:update2:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update10:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update11:*:*:*:*:*:* | ||
1.5.0CPE matchmatch criteria | cpe:2.3:a:sun:jdk:1.5.0:update12:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.